Ransomware victim disclosure
← All victimsAccesso
Claimed by Coinbasecartel · listed 23 hours ago
Status timeline
- ListedJul 28, 2026
- Data leakeddate unknown
At a glance
- Group
- Coinbasecartel
- Status
- Data leaked
- Country
- United Kingdom
- Sector
- Financial Services
- Listed on leak site
- Jul 28, 2026
About the victim
AI dossier — public-source company profileAccesso is a UK-based software company providing ticketing, point-of-sale, virtual queuing, and guest experience solutions for attractions, entertainment venues, and hospitality operators worldwide. The company serves theme parks, zoos, ski resorts, museums, stadiums, and restaurants with integrated platforms for revenue optimization and operational management.
- Industry
- Ticketing, Queuing & Guest Experience Software
Attack summary
Severity: high — Confirmed data publication by ransomware group targeting a software provider serving hundreds of venues globally. Compromise of ticketing/POS systems affects downstream clients and their customer data. Lack of specific proof count details prevents 'critical' rating, but the operational and data-exposure risk to the supply chain is significant.The coinbasecartel group claims to have compromised Accesso and published exfiltrated data. No specific details on data categories, volume, or operational impact are provided in the available excerpt.
Data the group says was taken
AI dossier — extracted from the leak post- Customer/client data
- Ticketing system records
- Point-of-sale transaction data
- Guest/visitor information
- Operational/business data
Original description
AI-summarised, not from the leak postAccesso is a UK-based technology company specializing in ticketing, queuing, and guest experience solutions for the leisure, entertainment, and attractions industry. It provides software platforms that help theme parks, ski resorts, cultural venues, and live events manage ticket sales, virtual queuing, and visitor engagement. The company operates globally, serving clients across North America, Europe, and beyond.
Sources
Source
Indexed 23 hours agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

